Kernel
by Google
CVEs (512)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20175 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A | ||
| CVE-2022-20169 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A | ||
| CVE-2022-20149 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A | ||
| CVE-2021-39726 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2022 | In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2021-39716 | Hig | 0.49 | 7.5 | 0.00 | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A | ||
| CVE-2021-39646 | Hig | 0.49 | 7.5 | 0.00 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A | ||
| CVE-2021-1045 | Hig | 0.49 | 7.5 | 0.00 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-195580473References: N/A | ||
| CVE-2017-13222 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2018 | An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576. | ||
| CVE-2017-13219 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2018 | A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller. Product: Android. Versions: Android kernel. Android ID: A-62800865. | ||
| CVE-2017-13214 | Hig | 0.49 | 7.5 | 0.02 | Jan 12, 2018 | In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:… | ||
| CVE-2017-13164 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2017 | An information disclosure vulnerability in the kernel binder driver. Product: Android. Versions: Android kernel. Android ID A-36007193. | ||
| CVE-2019-2213 | Hig | 0.48 | 7.4 | 0.00 | Nov 13, 2019 | In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2023-21054 | Hig | 0.47 | 7.2 | 0.01 | Mar 24, 2023 | In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20603 | Hig | 0.47 | 7.2 | 0.01 | Dec 16, 2022 | In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2017-13271 | Hig | 0.47 | 7.3 | 0.00 | Apr 4, 2018 | A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799. | ||
| CVE-2017-13270 | Hig | 0.47 | 7.3 | 0.00 | Apr 4, 2018 | A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744. | ||
| CVE-2017-13307 | Hig | 0.47 | 7.3 | 0.00 | Apr 4, 2018 | A elevation of privilege vulnerability in the Upstream kernel pci sysfs. Product: Android. Versions: Android kernel. Android ID: A-69128924. | ||
| CVE-2017-13306 | Hig | 0.47 | 7.3 | 0.00 | Apr 4, 2018 | A elevation of privilege vulnerability in the Upstream kernel mnh driver. Product: Android. Versions: Android kernel. Android ID: A-70295063. | ||
| CVE-2024-23716 | Hig | 0.46 | 7.0 | 0.00 | Sep 11, 2024 | In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-34725 | Hig | 0.46 | 7.0 | 0.00 | Jul 9, 2024 | In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. |
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A
- risk 0.49cvss 7.5epss 0.01
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A
- risk 0.49cvss 7.5epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-195580473References: N/A
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576.
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller. Product: Android. Versions: Android kernel. Android ID: A-62800865.
- risk 0.49cvss 7.5epss 0.02
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…
- risk 0.49cvss 7.5epss 0.00
An information disclosure vulnerability in the kernel binder driver. Product: Android. Versions: Android kernel. Android ID A-36007193.
- risk 0.48cvss 7.4epss 0.00
In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.47cvss 7.2epss 0.01
In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.47cvss 7.2epss 0.01
In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.47cvss 7.3epss 0.00
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799.
- risk 0.47cvss 7.3epss 0.00
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744.
- risk 0.47cvss 7.3epss 0.00
A elevation of privilege vulnerability in the Upstream kernel pci sysfs. Product: Android. Versions: Android kernel. Android ID: A-69128924.
- risk 0.47cvss 7.3epss 0.00
A elevation of privilege vulnerability in the Upstream kernel mnh driver. Product: Android. Versions: Android kernel. Android ID: A-70295063.
- risk 0.46cvss 7.0epss 0.00
In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.46cvss 7.0epss 0.00
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Page 12 of 26